[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

scheme48 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Package        : scheme48
Version        : 1.8+dfsg-1+deb6u1
CVE ID         : CVE-2014-4150
Debian Bug     : #748766

The function `scheme48-send-definition` in cmuscheme48.el blindly
overwrites the file /tmp/s48lose.tmp prior to sending it to the
inferior <scheme process.

This action will blindly overwrite files the user has permission
to modify, causing data-loss.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFTnzRF02K2KlS5mJARAoZXAJ9yBA2FD86QzN9rqfQT4pUOzlEfEQCfcRp6
Swfj36cDxXsyq9zVe+nuR38=
=sqKZ
-----END PGP SIGNATURE-----


Reply to: